Last updated: 11 August 2026

Privacy Policy

This notice explains how visitors’ personal data and messages sent to Andrea Pericoli’s professional AI chat are processed.

1. Data controller

The data controller is Andrea Pericoli. Questions and data-rights requests can be sent to and.pericoli@gmail.com.

2. Data processed

  • technical navigation data, including IP address, browser, request time and security logs;
  • questions, messages, recent chat history and generated answers;
  • optional answer feedback, including rating, reason, question and answer;
  • contact details and message content when a visitor chooses to send an email;
  • theme preference and session conversation stored locally in the browser.

Please do not submit sensitive, confidential or third-party information to the chat.

3. Purposes and legal bases

  • providing the website, chat and professional information, based on a legitimate interest in presenting professional activities;
  • responding to contact and collaboration requests and taking requested pre-contractual steps;
  • collecting feedback and improving the agent, based on the legitimate interest in service quality;
  • protecting security, preventing abuse and resolving technical problems;
  • using non-essential tracking only with consent, when applicable.

4. How the AI chat works

Messages are processed by the website infrastructure and sent to OpenRouter and the selected model provider. A limited portion of recent conversation may be included to preserve context.

When technical tracing is enabled, the question, answer, retrieved context, latency and diagnostic information may be stored in Supabase. Submitted feedback is stored to improve the service.

The chat is informational, may make mistakes and does not make automated decisions with legal or similarly significant effects.

5. Providers and recipients

Data may be processed, only as necessary, by Vercel for hosting and logs, OpenRouter and model providers for message generation, Supabase for technical traces and feedback, Notion when the embedded “Who I am” page is opened, and email providers when a visitor sends an email. LinkedIn, Substack and GitHub process data under their own policies when their links are opened.

6. Transfers outside the EEA

Some providers may process data in the United States or other countries outside the EEA. Transfers rely on GDPR mechanisms such as adequacy decisions, standard contractual clauses or other applicable safeguards stated by those providers.

7. Retention

  • browser chat history remains in sessionStorage until the session is closed or a new chat is started;
  • the theme preference remains until deleted by the user;
  • chat traces are retained for up to 90 days and feedback for up to 12 months;
  • emails are normally retained for no more than 24 months;
  • technical logs follow the infrastructure providers’ configured retention periods.

8. Your rights

Where provided by the GDPR, you may request access, correction, deletion, restriction, portability or object to processing, and withdraw consent without affecting previous processing. Requests can be sent to and.pericoli@gmail.com. You may also complain to the Italian Data Protection Authority.

9. Security and updates

Reasonable technical and organisational safeguards are used, although no online transmission or storage is risk-free. This notice may be updated when services or legal requirements change.